By Morey J. Haber, Chief Security Officer at BeyondTrust
In mergers and acquisitions (M&A), financial and legal due diligence has traditionally dominated the risk assessment process.
However, a growing body of cybersecurity analysis suggests that this approach is no longer sufficient, with acquirers increasingly inheriting unseen cyber liabilities and technical debt that only emerge after deal completion. In particular, identity infrastructure (both human and machine) has become a critical but frequently under-examined source of deal risk and post-acquisition high-cost mitigation.
Identity now functions as the effective perimeter of modern enterprise environments, meaning any failure to assess it during diligence can expose the acquiring organisation to immediate compromise upon integration.
Identity as the new perimeter
The modern enterprise no longer operates within a clearly defined network boundary. Cloud adoption, remote workforces, and SaaS proliferation have dissolved traditional perimeters, replacing them with identity centric access models.
Within this environment, mergers effectively combine two identity ecosystems, each with its own users , non-human identities, and entitlements. When this integration occurs without full visibility into identity posture, organisations risk importing pre-existing vulnerabilities directly into their core environment.
This is not merely theoretical. Acquirers often discover post-transaction that inherited systems contain dormant accounts, misconfigured privileges, and undocumented access pathways that were never captured in a formal audit process.
These exposures can be activated immediately once network connectivity is established, turning strategic acquisitions into operational liabilities.
The 100-to-1 machine identity problem
One of the most significant yet underappreciated risks in modern environments is the explosion of non-human identities (NHIs). These include service accounts, API keys, automation tools, AI agents, and machine-to-machine credentials that underpin digital operations.
In many organisations, machine identities now outnumber human users by more than 100 to 1. These identities often operate with persistent, high-level access privileges and limited security controls such as multi-factor authentication.
The scale of this machine identity population creates a systemic blind spot. While organisations invest heavily in human-focused security controls, machine identities frequently remain unmanaged and over-permissioned.
In an M&A context, this imbalance becomes particularly dangerous. When environments are connected, machine identities can provide immediate lateral movement opportunities for threat actors, bypassing traditional human-centric controls entirely.
Attackers think in graphs, not lists
A persistent weakness in traditional cybersecurity and IT due diligence is the reliance on siloed, checklist-based evaluation methods with different teams assessing different systems.
This fragmented approach fails to reflect how attackers operate. Rather than viewing systems in isolation, adversaries map relationships across environments.
To put it another way, defenders think in lists while attackers think in graphs, and this distinction is critical. A checklist may confirm that individual systems are secure in isolation, but it does not reveal how those systems interact to create compounded risk nor misconfigurations due to their interconnections.
In M&A scenarios, this graph-based attack surface becomes even more complex. Two previously separate identity systems are suddenly interconnected, often before a full relational mapping has been completed.
Identity debt and the shadow access challenge
Beyond explicit credentials and accounts, organisations accumulate what is increasingly described as identity debt. This includes orphaned accounts and legacy access permissions that persist long after their original purpose has expired.
These “shadow identities” are rarely visible in standard audits but can retain significant access rights. In many cases, they remain active within production systems for months or even years without detection.
The risk is amplified during M&A transactions. When two environments merge, identity debt is effectively doubled, bringing together two sets of unmanaged access pathways. This can include dormant administrative accounts, forgotten integrations, deprecated systems, and undocumented automation workflows.
Compounding this issue is the rise of AI-driven automation. Modern organisations increasingly deploy autonomous agents with elevated permissions to move and process data across systems.
These non-human actors often operate outside traditional governance frameworks, creating what amounts to a parallel identity ecosystem that is rarely captured in diligence processes.
Privilege is no longer static
Traditional security models assume privilege is a fixed attribute. That is, users are either administrators or they are not. In modern cloud and hybrid environments, however, privilege is dynamic, inherited and often indirect.
A user’s effective access can be shaped by group membership, inherited roles, misconfigured certificates, or outdated policy assignments. This concept of “true privilege” reflects the real-world permissions an identity possesses, rather than what is formally assigned.
One of the most effective mitigations remains the reduction of standing privileges, particularly local administrator rights to honour least privilege. Organisations that enforce just-in-time access models significantly reduce exposure to common exploit pathways, limiting the time window in which credentials can be misused.
The central implication for M&A leaders is clear: identity infrastructure is no longer a back-end IT concern but a core determinant of enterprise value and transaction risk.
Deals that fail to incorporate identity-centric cybersecurity diligence risk inheriting not just technical debt, but active and exploitable vulnerabilities embedded deep within acquired systems. As digital environments grow more interconnected and machine-driven, the ability to map, understand and control identity relationships will increasingly define whether acquisitions succeed or become costly liabilities.
